Skip to main content

Help us improve the Digital Marketplace - send your feedback

BOUNCE AGENCY LIMITED

SIM Resource Booking

Cloud-based platform for managing bookings, asset tracking, and access control. SIM Resource Booking combines resource reservations with asset lifecycle management—tracking equipment location, maintenance, and utilisation alongside room and workspace bookings. Automated safety inductions, permissions, and comprehensive reporting. Used by schools, NHS sites, and councils to manage resources and assets efficiently.

Features

  • Book shared resources: rooms, desks, labs, studios, equipment
  • Works on phone, tablet and desktop (no app required)
  • Integrated payments for chargeable bookings or events
  • Subscription and membership management (e.g. hot desk passes)
  • Public or private event booking with attendee limits and waitlists
  • Safety inductions and access steps for equipment or spaces
  • Asset lifecycle management, tracking, maintenance and depreciation
  • Live calendar, availability search and location filtering
  • Exportable reports: bookings, payments, audit trails, usage
  • Barcode/QR code asset identification and check-in/check-out

Benefits

  • One system to manage space, resources, users and payments
  • Ideal for NHS, councils, schools, libraries, labs and venues
  • Automates booking rules and approvals by user role or group
  • Enables safe access with induction tracking and entry control
  • Supports community access, room hire and events with payments
  • Subscription features for co-working, sports, or shared spaces
  • Public and staff bookings on any device, no install needed
  • Reduce equipment loss through systematic tracking
  • Flexible for training, public engagement, hybrid work or overflow
  • Integrated booking and asset management in one system

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at admin@bounce-agency.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 5 8 9 5 3 9 3 8 7 3 9 0 5 4

Contact

BOUNCE AGENCY LIMITED Andrew Downie
Telephone: 02074917401
Email: admin@bounce-agency.com

About your service

Service categories

Applications

Production and operations

  • Other operations

Service industry and public sector operations

  • Healthcare
  • Education
  • Public Order and Safety
  • Police
  • Defence
  • Social Security Administration
  • Adult Social Care
  • Children's Social Care
  • Other
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Our service is delivered via public cloud and accessed through web browsers (Chrome, Edge, Safari, Firefox). A stable internet connection is required. No installation or plug-ins are needed. Planned maintenance is scheduled outside UK business hours with at least 5 working days’ notice. Emergency maintenance is rare but may occur with shorter notice if necessary to address critical issues. The system is designed for desktop, tablet and mobile browsers; however, certain complex admin features are best managed on larger screens. SMS notifications are optional and require access to user phone numbers. Integration support may be required for legacy booking systems.
System requirements
  • Stable internet connection
  • Modern browser: Chrome, Edge, Safari or Firefox.
  • JavaScript and cookies must be enabled.
  • Smartphone with camera for barcode/QR asset scanning (optional)
  • Email access for notifications
  • SMS-enabled mobile for alerts
  • Desktop or tablet for admin users
  • No additional licences or plug-ins needed
  • Secure HTTPS access enabled on network
  • Compatible with public sector firewalls and configurations

User support

Email or online ticketing support
Yes
Support response times
We respond to all support queries within 4 working hours during standard service hours (Monday–Friday, 09:00–17:00 UK time).

Response time commitments:
- Critical issues: 4 hours (multiple users or core functionality affected)
- High priority: 4 hours (individual users or specific features)
- Medium priority: 8 hours (minor issues with workarounds)
- Low priority: Next working day (enhancement requests, general queries)

Weekend and out-of-hours:
Queries received outside standard hours, including weekends and public holidays, are responded to by 10:00 on the next working day. Emergency support available by arrangement for critical contracts.

Response times measured from query submission.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.2 AA
Web chat accessibility testing
We have conducted thorough testing of our web chat interface using multiple assistive technologies to ensure accessibility for all users.

Testing methods included:
- Screen readers: NVDA (Windows), JAWS (Windows), VoiceOver (macOS/iOS)
- Keyboard-only navigation without mouse input
- High-contrast modes (Windows High Contrast, browser extensions)
- Screen magnification software (ZoomText, Windows Magnifier)
- Voice control and speech recognition (Dragon NaturallySpeaking)

Testing was carried out by team members trained in assistive technology use, simulating real-world user scenarios including:
- Initiating chat sessions
- Reading and responding to messages
- Navigating chat history
- Accessing pre-chat forms
- Using emoji and attachments
- Managing notifications
- Closing and reopening conversations

Key accessibility features validated:
- All chat functions accessible via keyboard (Tab, Enter, Escape, Arrow keys)
- Screen reader announcements for new messages
- Clear focus indicators on interactive elements
- Sufficient colour contrast (4.5:1 minimum)
- Alternative text for visual elements
- ARIA live regions for dynamic message updates
- Logical tab order through interface

We have documented remaining limitations and maintain an accessibility roadmap. Testing occurs with each interface update to maintain WCAG 2.2 AA compliance. Our approach ensures inclusive support access for all users.
Onsite support
Yes
Support levels
We provide a single inclusive support level suitable for public sector organisations of all sizes. This includes access to our online ticketing system, email support, and telephone assistance during standard service hours (Monday to Friday, 09:00–17:00 UK time). All queries receive a response within 4 working hours.

Emergency or out-of-hours support can be arranged for contracts requiring critical coverage. Each customer is assigned a named support contact for continuity and familiarity.

Onboarding support is included as standard, covering account setup, permissions, branding, workspace configuration, and initial user training.

For clients requiring enhanced technical guidance, a dedicated Technical Account Manager (TAM) or Cloud Support Engineer can be provided for:
- Onboarding and implementation support
- Performance reviews and optimisation
- Integration planning and API guidance
- Custom development consultation
- Quarterly business reviews

This is available as a separate costed service, typically from £650/day depending on scope and duration.

We use a transparent support ticketing system, allowing users to set issue priority and monitor ticket status. Support performance is reviewed quarterly with enterprise customers to drive service improvements.

Our support model is designed to be clear, accountable, and tailored to the operational needs of NHS, education, and local authority users.
Support available to third parties
Yes
AI chatbot
No

Onboarding and offboarding

Getting started
Standard implementation takes 3 weeks from order to go-live. When a buyer adopts SIM Resource Booking, we deliver a structured onboarding process tailored to their operational and technical environment. It begins with a discovery session to define venue types, resource categories, asset types, user permissions, booking policies, and safety workflows. We configure the system accordingly, applying templates where appropriate and customising access controls to meet buyer needs.

We support integration with existing CRM systems (e.g. Microsoft Dynamics, Salesforce, or custom databases), ensuring booking activity, user access, and engagement data sync seamlessly into the buyer's digital ecosystem. We handle integration via secure API endpoints, with technical support throughout.

Live onboarding includes remote training for admins, coordinators and users, supported by downloadable guides, walkthrough videos, and a dedicated knowledge hub. We also offer onsite training for large or complex deployments.

Calendar integrations (e.g. Outlook, Google, ICS) and optional SSO setup are completed during onboarding. For buyers using kiosks or tablets for self-service booking, we provide UI configuration and access management.

A named onboarding lead ensures smooth delivery and handover. Post-launch, we offer a 30-day bedding-in period with enhanced support. This guarantees every buyer achieves a confident, fully-aligned rollout delivering immediate operational value.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
At contract end, users can extract all data securely via the admin dashboard or request a full export from our support team.

Data included in exports:
- Booking records (past, present, and future reservations)
- Asset registers and inventory records
- Equipment maintenance history and service logs
- Asset transfer and location history
- User accounts and permissions
- Audit logs and activity trails
- Documents and attachments
- System configurations and custom settings
- Payment and transaction records (if applicable)
- Induction completion records
- Reports and analytics data

Export options:
Data is provided in open, non-proprietary formats including CSV, JSON, XML, and PDF to support onward use or migration to alternative systems. Exports can be filtered by date range, location, or department.

Security and support:
All exports are encrypted in transit (TLS 1.2+) and access-controlled via role-based permissions. We provide clear step-by-step guidance, export templates, and data dictionaries to ensure safe and complete data extraction.

There is no additional charge for standard end-of-contract data exports. Dedicated support is available throughout the process to assist the buyer's IT team. We can schedule exports outside business hours to minimize operational impact.
End-of-contract process
At contract end, users are notified in advance and provided with a clear offboarding plan. All client data can be exported in open, non-proprietary formats (CSV, JSON, PDF) via the admin interface or with assistance from our support team. This includes booking records, user profiles, audit logs, documents, and configuration data. Standard data export and support are included in the contract price at no additional cost.

We provide read-only access to the system for up to 30 days post-contract, giving clients time to complete data extraction or handover. After this period, accounts are deactivated, and data is securely deleted in line with our ISO 27001–compliant data destruction policy.

Where required, optional paid services are available, including:
• Bespoke data transformation or formatting
• Extended access beyond 30 days
• Formal decommissioning reports
• Workshops to document workflows developed during the contract
• Technical consultancy for data migration to a new system

All post-contract services are quoted in advance and delivered in collaboration with the buyer’s technical team. Our goal is to ensure a smooth, secure, and compliant transition with no disruption to venue operations or service continuity. We align offboarding with NCSC guidance and government cloud security principles.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is fully responsive and accessible via mobile browsers without loss of core functionality. Interfaces are optimised for smaller screens, touch navigation, and reduced bandwidth environments. Some complex admin features (e.g., asset configuration, bulk operations) are streamlined for mobile, but all critical tasks—including resource booking, availability search, asset tracking, and dashboard views—are available on both mobile and desktop.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Our service includes a secure, browser-based interface with role-based access, supporting all major desktop and mobile web browsers. The interface features:

- Intuitive dashboard with real-time booking and asset status
- Drag-and-drop calendar for easy scheduling
- Visual floor plans for space selection
- Search and filter tools for resources and assets
- Quick-access booking forms and check-in/check-out
- Mobile-optimised touch interface
- Customisable widgets per user role
- In-app notifications and alerts
- Responsive design adapting to screen size
- Dark mode for accessibility

No software installation required. Users access via standard HTTPS connection with single sign-on (SSO) support.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have conducted comprehensive manual and automated interface testing using tools such as Axe, WAVE, and Lighthouse to assess compatibility with screen readers (e.g. NVDA, JAWS, VoiceOver) and keyboard-only navigation.

Key user journeys tested for accessibility include:
- Making and modifying bookings
- Checking availability and searching resources
- Managing assets and maintenance records
- Navigating dashboards and reports
- Completing check-in/check-out processes
- Accessing help documentation
- Submitting support requests

We engaged users with visual impairments in structured testing sessions to validate:
- Colour contrast ratios (minimum 4.5:1 for text)
- Focus states and keyboard navigation order
- Alternative text for images and icons
- Screen reader announcements for dynamic content
- Form field labels and error messages
- Button and link descriptions
- Heading structure and landmark regions

Testing revealed and we addressed:
- Improved focus indicators on interactive elements
- Enhanced ARIA labels for complex components
- Optimised tab order for logical flow
- Added skip navigation links
- Ensured all functionality available via keyboard

Accessibility refinements were made in line with WCAG 2.2 AA standards. We conduct ongoing testing with each major release and maintain an accessibility statement detailing conformance status.
API
Yes
What users can and can't do using the API
Our secure RESTful API allows authorised users to integrate SIM Resource Booking into third-party systems or automate workspace/resource management tasks.

What users can do:
• Create, update, and cancel workspace/resource bookings
• Query availability across locations or asset types
• Manage users, permissions, and group memberships
• Retrieve booking data for reporting or audit
• Configure alerts and sync bookings with calendars (e.g. Outlook, Google)

How users set up/make changes:
• API keys and authentication tokens are issued during onboarding
• Users can configure endpoints, filters, and data payloads via the API
• Admin users can automate onboarding or manage resources dynamically

Limitations:
• Some admin functions (e.g. billing setup, branding) are only available via the web interface
• API access is role-based and rate-limited (2000 requests/hour)
• Certain audit-level data and internal logs are restricted for security
• Create, update, and track assets (equipment, devices, vehicles)
• Record maintenance activities and service history
• Query asset location, status, and assignment
• Generate asset reports and depreciation schedules
Full API documentation is available in HTML and PDF formats and includes endpoint descriptions, usage examples, error codes, and setup guidance. An API sandbox is available for test integration.
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Buyers can customise core elements of the service to suit operational needs.

What can be customised:
- Asset categories, types, and custom fields
- Maintenance schedules and service templates
- Location hierarchies and transfer workflows
- Asset status definitions and lifecycle stages
- Depreciation methods and replacement thresholds
- Booking rules and approval workflows
- User roles and permission levels
- Notification preferences and alert templates
- Branding (logo, colour palette, email templates)
- Resource categories and booking time slots
- Pricing structures for paid bookings
- Report templates and dashboard layouts
- Induction steps and safety requirements
- Calendar integration settings (Outlook, Google)

How users can customise:
- Via the system settings panel for authorised administrators
- Through onboarding workshops with our support team
- Using API endpoints for integrations and automation
- Through bulk import tools for large-scale configuration

Who can customise:
- Buyers with administrative access
- Third-party integrators approved by the buyer
- Our support team, on request, for advanced configuration

All customisations are preserved through system updates. Changes are version-controlled and can be rolled back if needed. Customisation changes are logged in audit trails for compliance.

Scaling

Independence of resources
We guarantee user independence through a multi-tenant cloud architecture hosted on AWS UK regions. Each customer environment has logically isolated application containers, separate databases, and individual encryption keys. Compute and storage resources automatically scale based on individual demand, ensuring no performance degradation due to other users. Network traffic is prioritised per customer, with real-time monitoring and throttling to prevent resource contention. Role-based access controls and data partitioning ensure that users can only access their own data and resources. This design ensures consistent performance, data isolation, and security—regardless of concurrent usage by other organisations on the platform.

Analytics

Service usage metrics
Yes
Metrics types
We provide a full suite of real-time metrics via the admin dashboard and exportable reports. Metrics include: bookings (by space, time, user), utilisation rates, cancellations, no-shows, user activity, induction completions, asset tracking (location, status, transfers), maintenance schedules and completion, equipment lifecycle and depreciation, system uptime, and access logs. Reports filter by date, resource type, location, or asset category. All data exports in CSV or JSON for integration with CRMs or BI tools. Custom reporting available. Metrics support operational insight, performance optimisation, asset management, compliance monitoring, and strategic decision-making.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
Yes

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Users can securely export all data through the admin interface or API. Exports include workspace bookings, asset inventory records, equipment maintenance logs, asset location history, user records, space/resource configurations, safety induction data, activity logs, and audit trails. Data can be filtered by date, location, or asset, and downloaded in CSV, JSON, or PDF formats. Exports are encrypted in transit and access logged for compliance. Admins can schedule recurring exports or request support-assisted data extraction. API-based exports support integration with third-party systems such as CRMs or reporting tools. Documentation and guidance ensure safe, accurate export. All data extraction capabilities are included.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
  • JSON
  • PDF/A
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
  • JSON
  • XML

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
We guarantee 99.9% availability of the SIM Resource Booking platform, measured monthly. This equates to a maximum allowable downtime of approximately 43 minutes per month. Our service level agreement (SLA) includes proactive monitoring, rapid incident response, and robust failover systems to ensure high resilience.

If availability falls below the guaranteed threshold in any given month (excluding scheduled maintenance windows, force majeure, or customer-induced issues), users will be eligible for service credits as follows:
• 99.0% – 99.89%: 5% service credit
• 95.0% – 98.99%: 10% service credit
• Below 95.0%: up to 50% service credit

Service credits are calculated as a percentage of that month’s fee and can be applied as a credit against future invoices. Customers can request a service credit by raising a support ticket within 10 business days of the affected month.

We host on AWS UK regions, which offer enterprise-grade resilience, availability zones, and real-time failover. All updates are deployed using zero-downtime deployment processes, and customers are notified of any planned maintenance in advance.

We continuously monitor uptime through automated dashboards and alerting systems, and reports are available on request or through the client portal.
Approach to resilience
Our service is designed with resilience and continuity at its core. We host the SIM Resource Booking platform on AWS UK-based cloud infrastructure, which provides multiple layers of redundancy and failover across Availability Zones (AZs). These physically separate AZs are interconnected via low-latency links and enable us to distribute compute, storage, and database resources to eliminate single points of failure.

The service automatically scales to meet demand and reroutes traffic in the event of infrastructure failure. We use AWS services with built-in resilience, such as Amazon RDS (multi-AZ deployments), S3 (99.999999999% durability), and EC2 with auto-healing groups. Data is continuously replicated across secure zones and backed up regularly.

We implement automated monitoring, alerting, and failover processes to detect and respond to incidents in real-time. Disaster recovery procedures are tested regularly, and we can restore full functionality within a pre-agreed Recovery Time Objective (RTO) and Recovery Point Objective (RPO), guaranteed under 4 hours and 15 minutes, respectively.

All resilience design decisions align with the UK Government’s Cloud Security Principles, including asset protection and business continuity.

Full details of our infrastructure resilience design and disaster recovery processes are available on request to eligible buyers.
Outage reporting
We notify users of outages through multiple integrated channels to ensure prompt visibility and trust. Primary notifications are issued via automated email alerts to registered technical contacts and administrators. These alerts are sent immediately when any service degradation, partial outage or full outage is detected and include initial diagnostics, impact assessment and estimated time to resolution if available.

We maintain a dedicated, customer-accessible service status dashboard, which is updated in real time. This dashboard provides detailed, transparent information on current system status, components affected, incident history, and planned maintenance windows. It also allows users to subscribe to specific updates based on their role or system usage.

For enterprise buyers or integrators, we offer an optional status API, enabling integration of our service health information into your own dashboards or monitoring tools, and facilitating real-time automated polling of service status.

Following any outage, we publish incident summaries outlining cause, resolution steps, and mitigation measures. These are available through the dashboard and upon request.

Our outage reporting processes are designed to meet the needs of both operational and strategic stakeholders, support incident response planning, and ensure a high degree of transparency and accountability across all service tiers.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is strictly role-based and limited to authorised personnel only. We enforce Multi-Factor Authentication (MFA) for all administrative accounts and restrict access by IP where appropriate. User roles are defined by the principle of least privilege, with audit logs tracking all administrative actions. Support channels are segregated from production environments and access is logged and reviewed regularly. Sensitive data shared via support is encrypted in transit and at rest. Changes made via management interfaces are tracked through version-controlled logs, and suspicious access attempts trigger automated alerts for investigation.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
  • Other
Other security governance standards
Our service is hosted on AWS, which complies with ISO 27017, ISO 27018, SOC 2, and PCI DSS. We hold Cyber Essentials certification. We follow NCSC Cloud Security Principles, apply secure-by-design practices, including threat modelling, access control, and regular audits to ensure robust governance across development, deployment, and service operations.
Information security policies and processes
We follow a robust, risk-based information security management approach aligned to ISO/IEC 27001 principles. Our policies cover data protection, access control, encryption, secure software development, incident management, and business continuity.

All staff are trained on our information security policies at induction and through regular refresher sessions. Staff responsibilities are clearly defined in our Acceptable Use Policy and reinforced by contractual obligations and NDAs.

We operate a “secure by design” development approach, including regular vulnerability assessments, penetration testing, and adherence to NCSC Cloud Security Principles. Multi-factor authentication, least-privilege access, and encrypted data storage are enforced across all systems.

Security responsibilities are owned by the senior leadership team, with oversight from the Managing Director. A designated Security Lead manages policy compliance, incident response and risk reviews. Regular internal audits are conducted, and policy breaches are escalated to senior management immediately for investigation and remediation.

Incident response processes follow a structured approach: detection, triage, containment, eradication, recovery, and lessons learned. Serious breaches are reported to affected parties and regulators where applicable.

Security policies are reviewed quarterly or in response to major changes in threat landscape or service operations. Documentation is version controlled and securely stored with access logging.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We operate a robust configuration and change management process aligned with ISO/IEC 27001 and CSA CCM v4.0. All service components are tracked throughout their lifecycle using a secure configuration management system. Change requests are logged, impact-assessed, security-reviewed, tested, and documented in line with government’s Operational Security principle. Every change is evaluated for risks to availability, confidentiality, and integrity. Approved changes are version-controlled and deployed using automated pipelines. Emergency changes are logged, reviewed retrospectively, and fully audited. The entire process ensures minimal service disruption, maintains secure service continuity, and supports traceability, with comprehensive records retained for audit and compliance purposes.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We follow a proactive vulnerability management process aligned to ISO/IEC 27001 and CSA CCM v4.0. Threats are identified through automated vulnerability scanning tools, threat intelligence feeds (including NCSC advisories), and vendor alerts. All vulnerabilities are risk assessed based on severity, exploitability, and service impact. Critical patches are deployed within 24 hours; high-severity issues within 72 hours; all others within a defined patching window. We monitor emerging threats daily and implement continuous security updates via DevSecOps practices. Vulnerability reports and mitigation actions are logged and reviewed monthly by our security team to ensure accountability and continuous improvement.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We use real-time monitoring and automated alerting systems (AWS CloudWatch, GuardDuty) to detect potential compromises, anomalous behaviour and unauthorised access attempts. All logs are centralised and continuously analysed against known threat patterns. On identifying a potential compromise, our security team initiates our documented incident response protocol within 15 minutes. This includes triage, impact assessment, isolation of affected systems, and root cause analysis. High-priority incidents are escalated immediately to senior engineers and, if necessary, to the customer. We maintain detailed audit trails and generate post-incident reports. Our monitoring and response procedures align with CSA CCM v4.0 and ISO/IEC 27001 standards.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
We maintain pre-defined incident management processes for common events, including data breaches, service disruptions, and unauthorised access attempts. Users can report incidents via our online ticketing system, dedicated support email, or phone. All incidents are logged, triaged, and prioritised based on severity and impact. We follow defined escalation paths to ensure rapid response and resolution, including root cause analysis. Post-incident reports are shared with affected users and include a timeline, actions taken, and mitigation strategies. We maintain detailed incident logs for auditability and continual improvement, and align our processes with ISO/IEC 27035:2011 best practices.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
We offer a free 14-day trial of SIM Resource Booking with access to core features: workspace booking, asset tracking, team access, safety inductions, and admin tools. Excludes integrations (e.g. CRM, calendar sync) and payment setup. Trial access is set up manually and includes onboarding support. Extensions available on request.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
8%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
18%
Over £5,000,001
20%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Fccc8a9f-bf9c-4a21-a6d3-31bdfe3e82df
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • AWS ISO/IEC 27017:2015 – Cloud Security Controls
  • AWS ISO/IEC 27018:2019 – Protection of Personal Data
  • AWS SOC 1 / SOC 2 / SOC 3 reports
  • AWS CSA STAR Level 2 certification

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Plans to engage the contract workforce in deciding the most important workplace issues to address
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
    • How these flow down the supply chain and are monitored Illustrative examples include reporting, site visits, audits, etc.
    • Means of influencing staff, suppliers, customers, communities and/or any other appropriate stakeholders with respect to modern slavery risks relating to the contract
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
    • Methods for engaging with different parts of the community (including the education system and charities representing the community) and how communities come together to inform decisions, strategy and projects to leave a positive legacy for future generations
    • Plans for positive actions with community groups.
    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Collaborative ways of working with the supply chain to deliver additional environmental benefits in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
    • Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of issues relating to entering the contract workforce
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Content of the outreach activity is designed to suit the target cohort
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
    • Understanding barriers to access to health and social care services or employment opportunities e.g. digital inclusion
    • Inclusive and accessible recruitment practices, development practices and retention policies that support-focused activities including those provided in the Guide for line managers on recruiting, managing and developing which support people with a disability or health condition
    • Actions to invest in the physical and mental health and wellbeing of the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at admin@bounce-agency.com. Tell them what format you need. It will help if you say what assistive technology you use.